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(57) Abstract 



A computer-implemented method delivers goods purchased from a vendor web site without revealing the customer's identity or 
physical shipping address to the vendor computer (140). The method includes associating the identity and physical location of each 
customer with computer (100) linking information which is stored at a secure computer such as a secure provider computer (110) or 
banking computer (150). The customer computer (100) anonymously connects to the vendor web site (140) and orders goods without 
revealing his actual identity or physical location. The goods are given by the vendor to a common carrier in a package encoded by the 
vendor with a transaction identifier or a customer object. The common carrier retrieves the identity and address of the customer from 
the secure provider computer (110) using the transaction identifier or customer object and delivers the package to the customer's physical 
address. 
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ELECTRONIC COMMERCE WITH ANONYMOUS 
SHOPPING AND ANONYMOUS VENDOR SHIPPING 

5 TECHNICAL FIELD 

The present invention relates to a method and system of conducting 
electronic commerce which allows a customer to anonymously visit vendor web sites, 
anonymously purchase goods and anonymously receive goods without disclosing the 
customer's identification and home address information to the web site vendor. 

10 BACKGROUND ART 

At present day , more and more consumers are using a global 
communications network such as the Internet to do their shopping. On-line shopping 
allows users the freedom to quickly browse different vendor web sites, compare prices, 
locate hard-to-find items, shop across the country and the world, all within an abbreviated 

15 period of time. However, for good reasons, many people today are worried about privacy 
issues when using the Internet and World Wide Web ("the web"). Merely by visiting a 
web site, detailed information about the customer can be obtained, such as what computer 
the customer is using, where the computer is connected, which web site the customer last 
visited, etc. Furthermore, more and more sites are requiring that customers log into the 

20 site with personal information in order to use the services of the site. Many customers, 
however, do not wish to compromise their privacy and reveal their name and address since 
it will likely be placed in a database and sold as a part of a mailing list to other companies. 
Further, consumers worry about transmitting personal information such as credit card 
numbers or bank account numbers on-line, for fear of a third-party monitoring their 

25 transmission. 

At present, Internet billing systems are known that maintains the 
confidentiality of the customer information by an Internet access provider vis-a-vis a 
vendor web site. The Internet access provider creates access to the Internet through the 
secure provider's web site for the user. The provider then bills the customer's account 
30 with the provider or another specified account for transactions with outside vendors, 
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without the need for the customer to send his bank account number or credit card 
information to the vendor. The problem with these billing systems is that they do not 
provide complete privacy. While customers using such a billing system do not have to 
reveal their bank account numbers or credit card numbers to outside vendors, they do need 
5 to reveal their home addresses to the vendor so that the vendor can mail or ship the 
customer their order. Many customers, when shopping on-line, wish to remain completely 
anonymous to vendors in order to avoid future solicitations from the vendor, as well as 
having their names and addresses potentially added to a mailing list. Although anonymity 
is important, many shoppers enjoy the benefit of returning to vendor web sites which store 

10 information about the shopper (such as via "cookies") so that the same information need 
not be reentered each time and custom offerings and information can be communicated to 
the shopper upon revisiting a favorite web site. Accordingly, what is needed is a secure 
Internet e-commerce system that eliminates the need to provide vendors with both 
customers' actual identities and shipping addresses, and accordingly provides customers 

15 with complete anonymity. It would also be desirable to provide such an e-commerce 
system whereby the customer can remain anonymous but still visit web sites as a character 
or persona such that he or she is recognized upon return to the vendor web site. 
DISCLOSURE OF THE INVENTION 

In accordance with a preferred aspect of the present invention, a computer- 

20 implemented method of delivering goods is provided whereby good are purchased from a 
vendor having a vendor web site accessible over a computer network by a plurality of 
customers at physical locations. The customers have customer computers connected to the 
computer network for accessing the vendor web site and electronically purchasing goods 
therefrom. The method includes: (a) associating the identity and the physical location of 

25 each customer with a respective customer object via linking information; (b) storing the 
linking information at a secure computer at a location remote from the vendor web site; (c) 
anonymously connecting to the vendor web site by the customer computer using the 
identity of the customer object without revealing the identity and physical location of the 
customer; (d) ordering goods at the vendor web site by the customer using the customer 

30 computer, and upon initiation of an order by the customer, (i) automatically generating a 
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transaction identifier by the vendor computer, (ii) encoding a package of the goods ordered 
by the customer with the transaction identifier by the vendor and (iii) sending the 
transaction identifier together with the customer object to the secure computer by the 
vendor computer; (e) associating the transaction identifier sent by the vendor computer 

5 with the identity and physical address of the customer at the secure computer using the 
linking information and automatically forwarding the transaction identifier and associated 
identity and physical address of the customer to a computer of a common carrier; (f) 
delivering the encoded package to the common carrier by the vendor; and (g) reading the 
transaction identifier by the common carrier, using the identity and the physical location of 

10 the customer associated with the transaction identifier and physically delivering the 
package to the physical location of the customer. 

In an alternative preferred embodiment, the computer-implemented method 
of delivering goods comprises (a) associating the identity and the physical location of each 
customer with a respective customer object via linking information; (b) storing the linking 

15 information at a secure computer at a location remote from the vendor web site; (c) 
anonymously connecting to the vendor web site by the customer computer using the 
identity of the customer object without revealing the identity and physical location of the 
customer; (d) ordering goods at the vendor web site by the customer using the customer 
computer, and upon initiation of an order by the customer, encoding a package of the 

20 goods ordered by the customer with the customer object; (e) delivering the encoded 
package to the common carrier by the vendor; (f) providing the linking information to the 
common carrier; and (g) reading the customer object by the common carrier, retrieving the 
identity and the physical location of the customer associated with the customer object and 
physically delivering the package to the physical location of the customer. 

25 Desirably, the above methods further comprise sending information 

representing the cost of the goods ordered by the customer and the customer object from 
the vendor computer to a financial institution computer via the computer network for credit 
approval, ascertaining the credit status of the customer object, and automatically sending a 
message approving or declining credit to the customer to the vendor computer from the 

30 financial institution computer. Ascertaining the credit status of the customer object can also 
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include ascertaining the identity of the customer based on the linking information obtained 
by the financial institution from the secure provider. 

The step of anonymously connecting to the vendor web site may include 
revealing one or more customer characteristics to the vendor web site by the customer 

5 object so as to allow the vendor web site to use such customer characteristics to customize 
information and goods presented to the customer upon return to the vendor web site using 
the customer object. The step of anonymously connecting to the vendor web site is 
preferably performed automatically without customer interaction on at least some occasions 
by the customer object programmed to shop for the customer in accordance with directions 

10 specified by the customer. The customer object may be personified to the customer via the 
customer computer through the display of audio and/or visual display. 

The secure computer may comprise a secure provider computer allowing the 
customers to anonymously connect to the vendor web site therethrough, or alternatively, 
the secure computer can comprise the financial institution computer. 

15 In another preferred embodiment of the present invention, a computer 

character generating system is provided in the context of a computer system for offering 
goods, services and/or information from a vendor computer providing access to a vendor 
web site over a computer network including a plurality of customer computers connected 
to the network for accessing the vendor web site. The computer character generating 

20 system includes (a) a character generation program executable on the vendor computer and 
containing instructions for causing the vendor computer to generate an interactive vendor 
character which represents the vendor and interactively guides a customer through the 
vendor computer site, (b) the character generation program being operative to send 
character display commands to the customer computer when the customer computer has 

25 accessed the vendor web site causing the customer computer to display on a display device 
associated with the customer computer the interactive vendor character, (c) the interactive 
vendor character providing a trademark function for the vendor such that the interactive 
vendor character is identified with the vendor by customers who desire to acquire goods, 
services and/or information over the computer network from the vendor web site, the 

30 interactive vendor character further having a persona such that the vendor character will 
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respond to inputs from a customer computer representing communications by a customer in 
a manner representative of a human having particular personality traits acting in a 
representative capacity. 

Desirably, the vendor computer records the identities of customer computers 

5 which interact with the vendor web site and records historical data representing 
transactions of each customer computer with the vendor computer, and the vendor 
character responds to inputs from each customer computer based partially on the inputs 
and partially on the historical data in conjunction with the personality traits. The vendor 
character preferably has an artificial intelligence function which allows the vendor 

10 character to predict responses which would tend to elicit an acquisition by each customer 
computer based upon the historical data associated with such customer computer, and the 
interactive vendor character bases responses at least in part upon such predictions. The 
vendor character can also check for available goods, services and/or information requested 
by each customer computer and also checks for goods or services which are different from 

15 those requested by the customer computer but which are likely to be of interest to such 
customer computer based upon the historical data. The vendor character can be displayed 
with facial expressions, movement characteristics and voice accents associated with the 
personality traits. 

In yet another preferred embodiment of the present invention, an interactive 
20 computer-implemented method of offering goods, services and/or information is provided 
with a vendor computer providing access to a vendor web site over a computer network to 
a plurality of customer computers connected to the network for accessing the vendor web 
site. The method includes (a) providing a plurality of customer objects representing 
individuals who desire to acquire goods, services and/or information from the vendor sites, 
25 each customer object being provided with a set of user characteristics representing personal 
preferences and information about the individual; (b) providing a vendor persona object 
representing the vendor, the vendor persona object being provided with a set of vendor 
characteristics representing information about the goods, services and/or information 
offered by the vendor; and (c) visiting the vendor computer site via the network with a 
30 customer object such that the customer object and the vendor persona object dynamically 
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interact with one another to exchange one or more subsets of the set of user characteristics 
and vendor characteristics for determining whether the goods, services and/or information 
offered by the vendor computer site are of interest to the user persona object. 

The method desirably includes targeting a sales offer by a vendor computer 

5 to at least one customer computer via the secure provider computer based upon the 
purchasing interest and demographic information collected for at least one customer 
computer by the secure provider computer and provided to the vendor, wherein the 
customer object is configured by the customer to determine whether the sales offer will be 
presented to the customer computer. 

10 In yet a further preferred embodiment of the present invention, a method for 

providing advertising on the web site of a secure provider computer is provided comprising 
(a) providing a secure provider computer to allow customer computers connected to the 
secure provider computer to have access to authorized vendor offers on the secure provider 
web site; and (b) posting one or more vendor offers on the secure provider web site, 

15 wherein the offers are only viewable by the customer computers. 

In still a further preferred aspect of the present invention, a computer- 
implemented method for knowingly monitoring network navigation and purchasing history 
of a plurality of customers by a secure provider is provided,comprising: (a) requiring each 
customer to first establish an account with the secure provider by requiring each customer 

20 to agree to have the customer's demographic information and purchasing history tracked 
by the secure provider; (b) providing on-line access to a computer network to computers of 
customers who have established an account via a secure provider computer of the secure 
provider; and (c) tracking and storing the customers' demographic information and 
purchasing history by the secure provider computer as the customers update and change 

25 their demographic information and make purchases via their customer computers. 

Preferably, at least one customer computer is presented with an item to be 
purchased selected by the secure provider computer based on the customer's demographic 
information and purchasing history tracked by the secure provider. Further, a sales offer 
can be targeted by a vendor computer to at least one customer computer via the secure 

30 provider computer based on the customer's demographic information and purchasing 
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history collected by the secure provide computer and provided to the vendor in a modified 
form which does not include the customers 1 identity information, wherein the customer 
object is configured by the customer to determine whether the sales offer will be presented 
to the customer computer. 

5 In an even further preferred embodiment of the present invention, a method 

of providing outside vendor offers on a web site of a secure provider computer is 
provided, including (a) establishing a secure provider web site allowing member customer 
computers to have access to an area on the web site that posts outside vendor offers; and 
(b) configuring the secure provider web site so that the vendor offers are only viewable by 

10 the member customer computers. Desirably, only vendors who have signed up with the 
secure provider in advance are able to view the area on the web site that posts the outside 
vendor offers. 

BRIEF DESCRIPTION OF THE DRAWINGS 

FIG. 1 is a schematic diagram of a preferred embodiment of a computer 
15 system according to the present invention. 

FIG. 2 is a flow chart of the steps followed in a preferred method according 
to the present invention. 

FIG. 3 is a depiction of a sample secure provider web site. 

FIG. 4 is a depiction of a sample vendor web site. 
20 BEST MODES FOR CARRYING OUT THE INVENTION 

Referring to FIG. 1 , the computer system of the present invention comprises 
a network of interconnected computers connected via a global communications network 
such as the Internet 50. The network of computers comprise plurality of customer 
computers 100, a secure provider computer 110, a plurality of vendor computers 140, a 
25 plurality of bank computers 150 and a plurality of third party carrier or shipping computers 
180. Each computer comprises the typical components needed to connect to the Internet 
and World Wide Web, such as RAM and ROM memory, mass storage, microprocessor(s), 
display device, user input devices, etc. The secure provider computer 110 and vendor 
computers 140 also will typically include one or more server computers to allow provision 
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of web sites such as a secure provider web site and vendor web sites, which offer goods, 
services and other information desired. 

The present invention desirably allows a customer to shop on-line at vendor 
web sites in an anonymous fashion. To do so, a customer uses his customer computer 100 

5 (such as a home computer with dial-up connectivity to the Internet) to connect the secure 
provider computer 110 and login with a certificate based ID and password. Prior to 
conducting on-line shopping, the customer creates a customer object or on-line personna 
that represents the preferences of the customer. This is discussed in further detail below. 
The customer object which can be represented by a name (such as "GOLFO") and the 

10 customer's personal information, such as the customer's name and address, are matched up 
with linking information. This linking information is stored, in one embodiment, in a 
linking table stored in the database 130 of the secure provider computer 110. This linking 
table matches up each customer object with the customer's personal information which the 
customer wants shielded from the vendor web sites. Alternatively, the linking information 

15 can be stored in the database 170 of bank computer 150 so that only the bank, and not the 
secure provider, actually knows the true identity and address of the customer. In either 
case, the linking information is stored in a secure computer so as to shield the linking 
information from third parties, including the vendor. Using this linking table, the secure 
provider computer 110 or the bank computer 150 can determine which customer a given 

20 customer object represents. 

Once the customer computer 100 is connected to the secure provider 
computer 110, a secure connection pipeline 120 is provided between the customer 
computer 100 and the secure provider computer 110 in order to prevent transmissions 
between the customer computer 100 and the secure provider computer 110 from being 

25 monitored. Namely, after the customer joins the web site of the secure provider computer 
110, the customer computer 100 is preferably provided with software by the secure 
provider computer 110. This software enables the customer computer 100 to connect 
directly to the secure provider computer 110, along a known, fixed node-to-node route, 
without having to connect to the vendor web site through a different node-to-node network 

30 each time as is common over the Internet. Thus, to protect the privacy of the user, the 
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customer computers 100 are preferably connected to the secure provider computer 110 
through a virtual personal network ("VPN") which provides a private passageway or 
tunnel through the Internet. As is known in the Internet communications art, in a VPN, 
computers communicate with each other through firewall computers, so that the only 
5 addresses known are those of the firewall computers. This secure pipeline 120 allows the 
customer to connect directly, node-to-node, with a VPN, when there is communications 
between the secure provider computer and the vendor computer, so the only address that is 
revealed to the vendor is the address of the firewall computer. This allows customer 
computers 100 to communicate from within a network to vendor computers 140 without 
10 having their addresses revealed or access to any peripherals or devices on customer 
computer 100. 

With the secure connection, the customer computer 100 can anonymously 
connect to the web sites of various vendor computers 140 using the Internet via the secure 
provider's proxy servers. The customer computer 100 can browse for the web sites of 

15 vendor computers 140 of interest using various different search methods known in the art. 
When a customer computer 100 connects to a vendor web site of a vendor computer 140, 
the vendor computer 140 is provided only with the customer object, which identifies the 
customer as a fictitious entity without revealing personal information about the customer 
such as real name or address. When the customer computer 100 notifies the vendor 

20 computer 140 that the customer computer 100 would like to make a purchase, the vendor 
computer 140 contacts a bank computer 150 through the Internet to verify that the 
customer object on the customer computer 100 has sufficient funds to make the purchase. 
To facilitate the verification process, the vendor computer 140 forwards the customer 
object to the bank computer. The bank computer 150 obtains or is already provided with 

25 the linking information to link the customer object with personal information about the 
customer, including customer account information. Once the bank computer 150 
determines whether the customer object has sufficient funds to make the purchase, the 
bank computer 150 notifies the vendor computer 140 whether the customer has sufficient 
funds to make the purchase. In an alternate embodiment, the vendor computer 140 need 
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not contact a bank but can simply bill the secure provider computer 110 for the 
transaction, who will in turn bill the customer. 

Once a purchase by the customer has been approved, the vendor arranges 
for the package to be picked up by a third party carrier. The package, however, must be 
5 labeled with information that the shipper can use to ship the package to the correct address, 
but cannot contain the actual address of the customer, since it is to be shielded from the 
vendor. To accomplish this, the vendor computer 140, in a preferred embodiment, 
provides the third party carrier computer 180 with a transaction identifier and the customer 
object through the Internet to shipper computer 180. The vendor also places the 

10 transaction identifier only on the package. Once the shipper comes to the vendor to pick- 
up the package, the shipper, who is provided with or can ascertain the linking information, 
knows the address to match up with the transaction identifier. Alternatively, the vendor 
can simply attach the customer object to the package, such as in the form of a bar code or 
a label. The third party shipper computer 180 can then contact the secure provider 

15 computer 110 directly through a secure pipeline or through the Internet, to retrieve the 
customer's address from the database 130 or is provided ahead of time with the linking 
information to match up the customer object with the customer's actual name and address. 
Alternatively, where the linking information is not known to the secure provider and is 
known only to the bank, the shipper can retrieve or be provided with the linking 

20 information for the transaction identifier and/or the customer object from the bank. 

FIG. 2 illustrates a preferred method in accordance with the present 
invention. As shown in step 200, a customer computer 100 first connects to the web site 
of the secure provider computer 110, illustrated in FIG. 3, and joins the secure provider's 
service by filling out a standard form on the web site of the secure provider computer 110. 

25 When a customer signs up to use the secure provider web site and services, the customer is 
prompted to create a "persona" or customer object to be stored on a database 130 on the 
secure provider computer 1 10. In one embodiment, this object may have both a public and 
private segment to a digital certificate or key. In another embodiment, a linking table is 
also stored on the database 130 of the secure provider computer 110 which provides the 

30 link between the customer's personal information, such as the customer's name and 
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shipping address, and the customer's object such as a public key, but not the synonym, or 
name of the object. Alternatively, the linking table is stored only by banking computer 
and is not known by the secure provider. Thus, while the information about the customer 
object is stored by the secure provider, in the case where the customer wishes to remain 

5 anonymous to the secure provider, the linking information to link customer object to the 
actual customer is given only to the bank by the customer. The linking table is ultimately 
used to provide the bank computer with the account number or private key authorization of 
the customer and to provide the third party carriers with the actual name and address of a 
customer once the package has been labeled by the vendor with the customer object or 

10 transaction identifier. 

In one preferred embodiment, the customer can create and modify his 
customer object via a personalized home page stored on the web site of the secure provider 
computer 110. For example, if the customer is a golfer, the customer might create the 
persona or customer object named "GOLFO," which object can then be used to navigate 

15 anonymously on the Internet. In creating the persona, the customers can, for example, 
select an available name (such as GOLFO) and enter in detailed personal information about 
himself. The GOLFO persona thus functions as the customer's anonymous alter-ego and 
will contain personal information such as age, sex, interests, hobbies, shirt size, shoe size, 
likes, dislikes, merchandise the customer has an interest in, etc. This persona, GOLFO, 

20 along with all other customers 1 personas, is stored on the database 130 of the secure 
provider computer 110, which may or may not store the linking information as explained 
above. 

Once the customer joins the web site of the secure provider computer 110, 
the customer is provided with a customer object identifier number or certificate, also 
25 stored on database 130. The customer's object identifier number or certificate, but not 
their bank account information, credit card numbers or home address, is preferably stored 
on a "cookie" or database at the customer computer 100, and is also stored on secure 
provider computer 110. In this manner, when a customer logs into the secure provider 
web site using customer computer 100, the customer object identifier number or certificate 
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can be used by the secure provider computer 110 to identify the user as a customer of the 
web site of the secure provider computer 110. 

Once the customer computer 100 has been identified as a member of the 
web site of the secure provider computer 110, the customer computer 100 can then access 

5 the Internet through the web site of the secure provider computer 1 10 and begin to securely 
browse, as shown in step 210. 

When the customer computer 100 decides on a web site from which the 
customer would like to make a purchase, such as the vendor web site illustrated in FIG. 4, 
the customer computer 100 enters the web site of the vendor computer 140 as shown in 

10 step 220, as his "GOLFO" object or persona. Namely, when the customer computer 100 
enters the web site of the vendor computer 140, the vendor computer 140 is provided only 
with GOLFO 's persona information that is authorized for release. The GOLFO persona or 
object provides detailed demographic and psychographic information about the customer so 
that the vendor computer 140, if desired, can develop a relationship with the customer 

15 through his persona. For example, if the customer visits a golf merchant's web site on a 
regular basis to buy golf shirts, the golf merchant's vendor computer 140 could store a 
profile of the GOLFO persona. When the vendor computer 140 sees that GOLFO has 
returned to the web site, the vendor computer 140 can present the customer, through his 
GOLFO persona, with shirts the vendor may think GOLFO might like based upon the 

20 previous purchases of GOLFO, as seen by display 400 on the vendor web site. 

In other words, when a customer logs into a vendor web site, the customer 
will log in with a customer object that does not reveal the actual customer who is linked to 
the object. The information that is revealed to the vendor would simply be GOLFO at the 
address of the web site of the secure provider computer 110. In this manner, safe and 

25 private visitation of web sites can be achieved through the customer object. The customer 
object can also be programmed to navigate the Internet on its own, gather relevant 
information and then report back to the actual customer the information gathered based on 
the task(s) assigned to the customer object. 

In a further aspect of the present invention, the customer object is provided 

30 with a credit rating or credit history such that the vendor can determine whether to sell the 
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goods to the customer. Preferably, the customer object is provided with its own credit 
facility, which could include, for example, a virtual credit card. Such a virtual credit card 
is preferably given a name and icon representation so that the customer can easily purchase 
goods on-time by clicking on the credit card name or icon displayed at the participating 

5 vendor's web site. Use of such virtual credit card enables the customer object to readily 
purchase goods or services on credit. Credit card transactions, when authorized by the 
customer or customer object identifier, are preferably done through secure transaction 
protocols, such as digital signature and digital certificates. In such a case, the customer 
object itself can be provided with the digital signature and certificate information for use in 

10 purchasing items. 

Once a customer decides to make an on-line purchase from the secure web 
site, the customer preferably clicks on an icon, such as icon 410 shown in FIG. 4, 
representing the virtual credit card on the secure provider web site, as shown in step 230. 
A list of items selected can also be displayed in a "shopping cart" such as shown at display 

15 430 on the vendor web site. 

As shown in step 240, the vendor then forwards the customer's object, 
vendor number, transaction identifier, and the amount of the purchase to bank computer 
150. In one embodiment, the customer object comprises a public key and a private key 
authorization code. In one preferred embodiment, bank computer 150 is provided with a 

20 database 170 of the linking information of customer object or public key and customer 
information that allows the bank computer 150 or credit card company computer to 
determine who the actual customer is. In another embodiment, the bank computer 150 or 
credit card company can retrieve the customer object or public key from the secure 
provider computer 110 and therefore need not be in physical possession of the linking 

25 information. The bank computer 150 then determines whether or not to authorize the 
transaction. Preferably, it is desired that the bank not know the transactional information 
of the customer so that it cannot determine purchasing history and preferences of the actual 
customer. Thus, the bank can agree not to use or sell the customer's transactional 
information for solicitations or the like or, if possible, the bank need not know what is 

30 being purchased and from where, only that the customer has the money or credit to cover 
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the transaction. Thus, in the case where the secure provider is not provided with the 
linking information, the customer is assured that the bank is not monitoring his or her 
transactional information and that the secure provider, who is monitoring the transactional 
information, cannot link the customer's actual identity to the customer object. 

5 In another embodiment, vendor computers 140 can contact the secure 

provider computer 110 instead of bank computer 150 to authorize payment. The secure 
provider computer 110 can either bill the customer, or the customer can create a 
credit/debit account with the secure provider computer 110. The vendor computer 140 can 
send the secure provider computer 110 a bill for the purchases of the customer computer 

10 100. The secure provider computer 110, in turn, can send a bill to the customer computer 
100, or, if the customer computer 100 has a credit or debit account established with the 
secure provider computer 110, the secure provider computer 110 could adjust the 
customer's account accordingly. In another embodiment, the secure provider computer 
110 can engage in electronic bill presentation to customer computer 100, and transmit 

15 information about the request for payment to bank computer 150. 

Once the bank computer 150 has authorized the purchase, as shown in step 
250, the bank computer 150 returns the vendor number, the transaction identifier and/or 
the customer object or public key, and the approval of the transaction back to the vendor 
computer 140 or to the secure provider computer 110, depending upon which computer 

20 transmitted information about the request for payment to bank computer 150. Upon 
approval of the transaction, the vendor readies the goods for anonymous shipment as 
explained below. 

A key aspect of the present invention is the secure and anonymous shipping 
protocol used. This secure and anonymous method is provided whereby the customer can 

25 have the vendor ship the items ordered to the customer without revealing the customer's 
name, address or other information about the customer to the vendor. In one preferred 
embodiment, the present invention uses the transaction identifier that is generated once the 
customer object decides to purchase given items. As shown in step 260, the vendor 
computer 140, once ready to ship the items, contacts an authorized shipper (e.g., a carrier 

30 who has previously contracted with the secure provider) such as carrier computer 180 and 
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discloses only the transaction identifier to the carrier computer 180. In another 
embodiment, the vendor computer 140 provides the carrier computer 180 with the 
customer object (such as "GOLFO"). As shown in step 270, the carrier computer 180 
then contacts the secure provider computer 110 or the bank computer 150 as the case may 

5 be, which then matches up the transaction identifier with the customer. The customer 
information is then relayed by the secure provider computer 110 or bank computer 150 to 
the carrier computer 180 who can then ship the items directly to the customer now 
knowing the address of the customer. Thus, while the secure provider and/or the bank and 
the shipping company know who the customer is, advantageously, the customer's actual 

10 identity is shielded from the vendor. 

The customer object can also be used for various other purposes. Thus, in 
another aspect of the invention, the customer object or persona can gather information on 
behalf of the customer and then can communicate with the customer interactively, through 
visual and/or aural means, by using interactive computer techniques such as video 

15 playback and voice synthesis to allow the persona to verbally and/or textual describe what 
information was found. Of course, such information can also be provided in traditional 
formats such as text on the computer screen. In a further aspect of the present invention, 
vendor/customer object interaction can occur through e-mail and e-mail systems can be 
used to further vendor/customer relationships at the object or persona level. In addition, 

20 through e-mail, the secure provider can make direct offerings to the customer whether or 
not the secure provider knows the actual identity of the customer. Thus, vendors and the 
secure provider can send offerings by e-mail to customer objects provided with their own 
e-mail addresses and the customer object can respond to such e-mails with return e-mail or 
by visiting the vendor or secure provider web site. 

25 In order to provide for secure transmissions over the Internet, the present 

invention can use different encryption methods to provide users with anonymity, and to 
prevent third parties from improperly obtaining a user's credit card number or bank 
account number. To this end, in one preferred embodiment, the system uses an RSA 
public key encryption. As is known to those skilled in the computer security art, RSA key 

30 technology has two main attributes. First, it can be the basis of a digital signature system. 
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Second, it can be used for storing encryption information. In a RSA digital signature 
system, the public key is used to verify the digital signature. The private key is used to 
sign one's signature for a block of data. Holders of public keys can verify a purchase by 
requesting that the purchaser digitally sign the block of data. If the signature matches up 

5 with the public key, the identity of the purchaser has been confirmed, and the seller can go 
forward and arrange for the shipment of the device with a third party shipper. 

The customer computer 100 is preferably provided with a private key, while 
the public key is stored on the database 130. The public key will contain information such 
as a customer object and a customer bank account or credit card number. Most 

10 importantly, the public key will not include information such as the customer shipping 
address, as is required in prior art electronic commerce systems. Once the customer 
computer 100 has a public key and a private key assigned, the customer computer 100 can 
then dial onto the Internet through the secure provider computer 110 to begin browsing. 

When a customer computer 100 enters the web site of the vendor computer 

15 140, the vendor computer 140 is provided with the public key. When a customer 
computer 100 notifies the vendor computer 140 that the customer would like to make a 
purchase from the vendor web site 140, the public key, the transaction number and the 
amount of the purchase is then forwarded by the vendor computer 140 to a bank computer 
150. In a preferred embodiment, bank computer 150 will be provided with access to a 

20 database 170 of all public keys. The bank computer 150 can then request that the 
customer computer 100, using the private key, "sign" for the purchase. Based upon the 
response from the customer computer 100, and upon the customer's credit history, the 
bank computer 150 decides whether or not the transaction will be approved. Once the 
transaction is approved, the vendor computer 140 is notified. The vendor computer 140 

25 can then forward the item purchased by the customer with a transaction number or 
customer object to a third party carrier as explained above. Using this transaction number 
or customer object, the carrier computer 180 will be able to retrieve the customers name 
and home address from the secure provider computer 1 10, or the bank computer 150, and 
can then deliver the package to the customer. 
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In another preferred embodiment of the present invention, customers can 
opt into having the secure provider track their on-line surfing activities and their 
preferences. This is in contrast to web sites which track surfing activity unbeknownst to 
the user. With the present invention, the customer knows ahead of time, by signing up 

5 with the secure provider, that the secure provider will be tracking surfing and transactional 
habits so as to better serve the customer. For example, by monitoring the browsing habits 
and purchasing habits of customer computers 100, the secure provider computer 1 10 can 
determine commonly purchased items or popular vendors. Additionally, the monitoring of 
browsing habits can aid the secure provider computer 110 in predicting future purchases or 

10 services required by the customer object. Using this information, the secure provider can 
purchase large quantities of items commonly purchased by its members, and act as a 
wholesaler for its members, making special deals with the vendors. 

The customer is encouraged by the secure provider to use and educate the 
customer object so that the secure provider can have real-time information to provide just- 

15 in-time or just-ahead-of-time product offerings to the customer or customer object. The 
secure provider computer 110, which will have access to all of the customer data, but not 
necessarily to the customers identity or address information, can also provide the stored 
demographic and preference information to vendor computers 140 without compromising 
the identity of the customer. In this manner, the provider could allow vendors to send 

20 information to targeted object groups which would not be bothersome to the customer since 
his or her object could make the decision whether to accept the offering from the vendor 
and/or present the offering back to the customer based on the preferences set by the 
customer. Thus, the customer object identifier can be, in effect, a screener of 
"unsolicited" offerings from vendor computers 140. Additionally, the secure provider 

25 computer 110 can conduct market research with a depth unavailable using traditional 
methods. Thus, if the customer computers 100 using customer object identifiers stored on 
the secure provider computers 110 use such object identifiers for many different shopping 
missions, the secure provider computer 110 would have access to data about the entire 
buying habits of its customers. For example, the secure provider database 130 would 

30 include information indicating that particular consumers like BMW automobiles and golf 
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sweaters, whereas other consumers like Audi automobiles and cycling jerseys. The secure 
provider computer 110 could conduct statistical studies to uncover correlations that would 
identify potential marketing and buying opportunities. For example, without breaching its 
obligation of confidence with respect to individual consumer information, the secure 
5 provider could conduct a market research study for a manufacturer of golf sweaters and 
advise the manufacturer to focus on BMW owners rather than Audi owners. 

In another preferred embodiment of the present invention, vendor computers 
140 can provide special offers to be displayed on the web site of the secure provider 
computer 110. To accomplish this, the secure provider computer 110 can provide a web 

10 page which vendor computers 140 can log onto with a standardized form for the vendors to 
fill out. The secure provider computer 110 can then post each of the standardized forms 
onto a virtual bulletin board to a web site available only to customer computers 100. The 
advantage this embodiment provides is that customers need not shop on a non-secure web 
site to receive the special offers, since the offers will come via the secure provider 

15 computer 1 10. These offers can be posted for all customer computers 100 to see, or can 
be directed to specific customer computers 100. Further, customers will have the option of 
deciding whether or not they wish to even see the offer. 

In order to prevent price pirating, the vendor advertisements are preferably 
posted to an area of the web site of the secure provider computer 110 that is only 

20 accessible to customer computers 100. Accordingly, vendor computers 140 will not be 
able to view the offers coming from other vendor computers 140. Alternatively, 
authorized vendor computers 140 (i.e., vendors signing up with the secured provider to 
reach the secure provider's customers) may be allowed to see one another's offers but 
unauthorized vendors cannot see the offers of authorized vendors. 

25 In yet another aspect of the present invention, an interactive, intelligent 

virtual vendor representative object (such as a virtual salesperson object) is provided as a 
guide to a given web site. For instance, when accessing a web site of a vendor computer 
140, the vendor object can be provided with a persona such that instead of passively 
navigating through the site, an animated character or vendor persona is encountered by the 

30 customer. The vendor persona then takes on the role of a virtual salesperson, asking 
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questions of the customer and making recommendations based on the responses by the 
customer. By interaction with the customer object identifier, the vendor object becomes 
cumulatively knowledgeable, can store customer preferences and history and proactively 
pursue the vendor/ vendee relationship. 

5 Notoriety of the vendor character or persona apart from the web site is 

desirable and is preferably enhanced through advertising (such as through print media, TV, 
radio, etc.) such that the persona becomes "branded" or closely associated with the vendor 
company and serves as a trademark or service mark of the company. The perception by 
the customer that the vendor character represents the company as a trademark is desirable 

10 for a number of reasons, such as to impart a feeling of familiarity with the character when 
encountered, create a desire on the customer's part to initially visit the web site to interact 
with the character, and enhance the customer's comfort level in interacting with the 
character. All of these benefits will then ultimately help the vendor increase traffic to the 
web site and raise the comfort level of the customer when he or she visits the web site. 

15 In a related aspect of the present inventions, intelligent, virtual customer 

objects are desirably provided so that the customer need not search the Internet on his 
own, interact with vendor objects or personae encountered, or deal with the everyday 
hassles of the Internet (expired URLs, slow connections, information overload, etc.). The 
customer can be a customer persona which can be visually displayed on the computer 

20 screen and be customized or designed to physically resemble the customer's human 
characteristics or resemble a caricature of the customer, a familiar character, an animal, or 
any other visible object. Alternatively, the customer object identifier may be nonvisual or 
simply represented by a file, icon, programming object, etc. Preferably, a customer can 
set up a customer object with all of the characteristics, personal information, history and 

25 demographic information about the customer such that the object identifier, and not the 
customer, can expend the "effort" of searching the Internet, shopping and gather 
information useful or desired by the customer. It should be noted that the customer object 
is likely to be more proficient than the customer in learning to use Internet or Intranet tools 
that require more effort, knowledge or know how that the average consumer possesses or 

30 desires to exercise. 
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For instance, a customer object or persona can be provided with 
individualized characteristics about the customer, such as that the customer is male, 32 
years old, a cigar smoker, a wine enthusiast, a tennis player, drives a sedan, owns a house, 
likes gardening, etc. The more information supplied to the persona, the more the persona 

5 takes on the full characteristics of the customer and enables a "smarter" persona when the 
persona is searching for information. By way of example, if the customer wants the 
persona to shop for light-weight sweaters in a size large, but customer forgets to tell the 
persona that he does not like the color red, the persona may collect possible sweaters to 
buy including unwanted red sweaters. The customer, upon discovering that red sweaters 

10 were located by his persona, can add a new characteristic to the persona that he does not 
like red sweaters for future search purposes. The more information supplied to the 
persona, the more intelligent it becomes. 

The software provided to both the vendors and customer computers can also 
allow generation of interactive characters. In this regard, the browser of the customer 

15 computer could be provided with the necessary "plug-ins" (such as a Java plug-in or 
ActiveX control) to allow the rendering of an interactive character on the video screen of 
the customer computer. 

Further, by using artificial intelligence (AI) techniques such as neural- 
network learning, the customer object or persona can be programmed to learn desired and 

20 undesired characteristics of the customer based on continued interaction between the 
persona and the customer and based on existing preferences. Thus, if the customer has the 
customer persona shop for sweaters, shorts and ties and merchandise is found including 
red sweaters, red shorts and red ties, and the customer selects such items in colors other 
than red, the persona can "learn" through AI techniques that the customer likely does not 

25 like the color red for clothing items and thus, when sufficiendy confident in its assessment, 
will no longer shop for red clothing. Thus, the more and more the customer interacts with 
his persona, the "smarter" the persona becomes and interaction between customer and 
persona is highly encouraged by the present invention. 

Another aspect of the present invention is that the vendor objects can 

30 interact with the customer objects in a virtual shopping encounter, as if the customer 
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wandered into the store of the vendor and was approached by a salesperson. The customer 
object would relate his preferences (or a subset thereof) to the vendor object who may have 
the items desired by the customer object. If the vendor object, however, does not have 
such an item in stock, it may use the information of the customer object to intelligently 

5 recommend a different item. For instance, if the customer object is looking to buy a 
BMW or Mercedes but the vendor object only has AUDIs, it may recommend to the 
customer object that it consider an AUDI since it deduced that this customer may like 
German-made cars. If the customer object did not specify that it did not like Audi's, it mat 
accept the recommendation from the vendor object. The more often the vendor object 

10 interacts with the customer object, the more each knows or learns of the other's 
preferences, needs and offerings. Such an ever-growing object interrelationship can 
greatly enhance the vendor-customer relationship. 

As these and other variations and combinations of features discussed above 
can be utilized without departing from the present invention as defined by the claims, the 

15 foregoing description of the preferred embodiments should be taken by way of illustration 
rather than by way of limitation of the present invention. 
INDUSTRIAL APPLICABILITY 

The present invention is applicable to the retail industry or elsewhere where 
vendors may wish to display their goods or services at a web site on the Internet and allow 

20 customers to browse and make purchases from a vendor web site anonymously. 
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CLAIMS: 

1. A computer-implemented method of delivering goods purchased 
from a vendor having a vendor web site accessible over a computer network by a plurality 
of customers at physical locations, the customers having customer computers connected to 
5 the computer network for accessing the vendor web site and electronically purchasing 
goods from the vendor web site, comprising: 

(a) associating the identity and the physical location of each customer 
with a respective customer object via linking information; 

(b) storing said linking information at a secure computer at a location 
10 remote from the vendor web site; 

(c) anonymously connecting to the vendor web site by the customer 
computer using the identity of the customer object without revealing the identity and 
physical location of the customer; 

(d) ordering goods at the vendor web site by the customer using the 
15 customer computer, and upon initiation of an order by the customer, (i) automatically 

generating a transaction identifier by the vendor computer, (ii) encoding a package of the 
goods ordered by the customer with the transaction identifier by the vendor and (iii) 
sending the transaction identifier together with the customer object to the secure computer 
by the vendor computer; 
20 (e) associating the transaction identifier sent by the vendor computer 

with the identity and physical address of the customer at the secure computer using the 
linking information and automatically forwarding the transaction identifier and associated 
identity and physical address of the customer to a computer of a common carrier; 

25 (f) delivering the encoded package to the common carrier by the 

vendor; and 

(g) reading the transaction identifier by the common carrier, using the 
identity and the physical location of the customer associated with the transaction identifier 
and physically delivering the package to the physical location of the customer. 
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2. The method of claim 1, further comprising sending information 
representing the cost of the goods ordered by the customer and the customer object from 
the vendor computer to a financial institution computer via the computer network for credit 
approval, ascertaining the credit status of the customer object, and automatically sending a 

5 message approving or declining credit to the customer to the vendor computer from the 
financial institution computer. 

3. The method of claim 2, wherein the secure computer comprises the 
financial institution computer. 

4. The method of claim 2, wherein ascertaining the credit status of the 
10 customer object includes ascertaining the identity of the customer based on the linking 

information obtained by the financial institution from the secure provider. 

5. The method of claim 1, wherein the step of anonymously connecting 
to the vendor web site includes revealing one or more customer characteristics to the 
vendor web site by the customer object so as to allow the vendor web site to use such 

15 customer characteristics to customize information and goods presented to the customer 
upon return to the vendor web site using the customer object. 

6. The method of claim 1, wherein the step of anonymously connecting 
to the vendor web site is performed automatically without customer interaction on at least 
some occasions by the customer object programmed to shop for the customer in 

20 accordance with directions specified by the customer. 

7. The method of claim 1, wherein the customer object is personified to 
the customer via the customer computer through the display of audio and/or visual display. 

8. The method of claim 1, wherein the secure computer comprises a 
secure provider computer allowing the customers to anonymously connect to the vendor 

25 web site therethrough. 

9. A computer-implemented method of delivering goods purchased 
from a vendor having a computer web site accessible over a computer network by a 
plurality of customers at physical locations, the customers having customer computers 
connected to the computer network for accessing the vendor computer site and 

30 electronically purchasing goods from the vendor web site, comprising: 



WO 00/14648 



PCT/US99/20348 



-24- 

(a) associating the identity and the physical location of each customer 
with a respective customer object via linking information; 

(b) storing said linking information at a secure computer at a location 
remote from the vendor web site; 

5 (c) anonymously connecting to the vendor web site by the customer 

computer using the identity of the customer object without revealing the identity and 
physical location of the customer; 

(d) ordering goods at the vendor web site by the customer using the 
customer computer, and upon initiation of an order by the customer, encoding a package 

10 of the goods ordered by the customer with the customer object; 

(e) delivering the encoded package to the common carrier by the 

vendor; 

(0 providing the linking information to the common carrier; and 
(g) reading the customer object by the common carrier, retrieving the 
15 identity and the physical location of the customer associated with the customer object and 
physically delivering the package to the physical location of the customer. 

10. The method of claim 9, further comprising sending information 
representing the cost of the goods ordered by the customer and the customer object from 
the vendor computer to a financial institution computer via the computer network for credit 

20 approval, ascertaining the credit status of the customer object, and automatically sending a 
message approving or declining credit to the customer to the vendor computer from the 
financial institution computer. 

1 1 . The method of claim 10, wherein the secure computer comprises the 
financial institution computer. 

25 12. The method of claim 10, wherein the secure computer comprises a 

secure provider computer allowing customers to anonymously connect to the vendor web 
site therethrough. 

13. The method of claim 10, wherein ascertaining the credit status of the 
customer object includes ascertaining the identity of the customer based on the linking 
30 information obtained by the financial institution from the secure provider. 
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14. The method of claim 9, wherein the linking information is 
transmitted to a computer of the common carrier via the computer network. 

15. The method of claim 9, wherein the step of anonymously connecting 
to the vendor web site includes revealing one or more customer characteristics to the 

5 vendor web site by the customer object so as to allow the vendor web site to use such 
customer characteristics to customize information and goods presented to the customer 
upon return to the vendor web site using the customer object. 

16. The method of claim 9, wherein the step of anonymously connecting 
to the vendor web site is performed automatically without customer interaction on at least 

10 some occasions by the customer object programmed to shop for the customer in 
accordance with directions specified by the customer. 

17. The method of claim 9, wherein the customer object is personified to 
the customer via the customer computer through the display of audio and/or visual display. 

18. In a computer system for offering goods, services and/or information 
15 from a vendor computer providing access to a vendor web site over a computer network 

including a plurality of customer computers connected to the network for accessing the 
vendor web site, a computer character generating system comprising: 

(a) a character generation program executable on the vendor computer 
and containing instructions for causing said vendor computer to generate an interactive 

20 vendor character which represents the vendor and interactively guides a customer through 
the vendor computer site, 

(b) said character generation program being operative to send character 
display commands to said customer computer when said customer computer has accessed 
the vendor web site causing said customer computer to display on a display device 

25 associated with the customer computer said interactive vendor character, 

(c) said interactive vendor character providing a trademark function for 
the vendor such that said interactive vendor character is identified with said vendor by 
customers who desire to acquire goods, services and/or information over the computer 
network from said vendor web site, said interactive vendor character further having a 

30 persona such that said vendor character will respond to inputs from a customer computer 
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representing communications by a customer in a manner representative of a human having 
particular personality traits acting in a representative capacity. 

19. A system as claimed in claim 18, wherein said vendor computer 
records the identities of customer computers which interact with the vendor web site and 

5 records historical data representing transactions of each customer computer with the 
vendor computer, and wherein said vendor character responds to inputs from each 
customer computer based partially on said inputs and partially on said historical data in 
conjunction with said personality traits. 

20. A system as claimed in claim 19, wherein said vendor character has 
10 an artificial intelligence function which allows said vendor character to predict responses 

which would tend to elicit an acquisition by each customer computer based upon the 
historical data associated with such customer computer, and said interactive vendor 
character bases responses at least in part upon such predictions. 

21. A system as claimed in claim 20, wherein said vendor character 
15 checks for available goods, services and/or information requested by each said customer 

computer and also checks for goods or services which are different from those requested 
by said customer computer but which are likely to be of interest to such customer 
computer based upon the historical data. 

22. A system as claimed in claim 18, wherein said vendor character is 
20 displayed with facial expressions, movement characteristics and voice accents associated 

with said personality traits. 

23. An interactive computer-implemented method of offering goods, 
services and/or information from a vendor computer providing access to a vendor web site 
over a computer network to a plurality of customer computers connected to the network 

25 for accessing the vendor web site, comprising: 

(a) providing a plurality of customer objects representing individuals 
who desire to acquire goods, services and/or information from said vendor sites, each said 
customer object being provided with a set of user characteristics representing personal 
preferences and information about the individual; 
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(b) providing a vendor persona object representing the vendor, said 
vendor persona object being provided with a set of vendor characteristics representing 
information about the goods, services and/or information offered by the vendor; and 

(c) visiting said vendor computer site via the network with a customer 
5 object such that said customer object and said vendor persona object dynamically interact 

with one another to exchange one or more subsets of said set of user characteristics and 
vendor characteristics for determining whether the goods, services and/or information 
offered by the vendor computer site are of interest to said user persona object. 

24. The method of claim 23, further comprising targeting a sales offer 

10 by a vendor computer to said at least one customer computer via said secure provider 
computer based upon the purchasing interest and demographic information collected for 
said at least one customer computer by said secure provider computer and provided to said 
vendor, wherein said customer object is configured by the customer to determine whether 
the sales offer will be presented to the customer computer. 

15 25. A method for providing advertising on the web site of a secure 

provider computer, the method comprising: 

(a) providing a secure provider computer to allow customer computers 
connected to said secure provider computer to have access to authorized vendor offers on 
the secure provider web site; and 

20 (b) posting one or more vendor offers on the secure provider web site, 

wherein said offers are only viewable by the customer computers. 

26. A computer-implemented method for knowingly monitoring network 
navigation and purchasing history of a plurality of customers by a secure provider 
comprising: 

25 (a) requiring each customer to first establish an account with the secure 

provider by requiring each customer to agree to have the customer's demographic 
information and purchasing history tracked by the secure provider; 

(b) providing on-line access to a computer network to computers of 
customers who have established an account via a secure provider computer of the secure 

30 provider; and 
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(c) tracking and storing the customers' demographic information and 
purchasing history by the secure provider computer as the customers update and change 
their demographic information and make purchases via their customer computers. 

27. The method of claim 26, further comprising presenting at least one 
5 customer computer with an item to be purchased selected by the secure provider computer 

based on the customer's demographic information and purchasing history tracked by the 
secure provider. 

28. The method of claim 26, further comprising targeting a sales offer 
by a vendor computer to at least one customer computer via the secure provider computer 

10 based on the customer's demographic information and purchasing history collected by the 
secure provide computer and provided to the vendor in a modified form which does not 
include the customers' identity information, wherein said customer object is configured by 
the customer to determine whether the sales offer will be presented to the customer 
computer. 

15 29. A method of providing outside vendor offers on a web site of a 

secure provider computer comprising: 

(a) establishing a secure provider web site allowing member customer 
computers to have access to an area on the web site that posts outside vendor offers; and 

(b) configuring the secure provider web site so that the vendor offers are 
20 only viewable by the member customer computers. 

30. The method of claim 29, wherein only vendors who have signed up 
with the secure provider in advance are able to view the area on the web site that posts the 
outside vendor offers. 
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